🚨 @KelpDAO decided to move rsETH to Chainlink CCIP 👀
📊 The step came after considering the @LayerZero_Core architecture as the main reason for the April hack
⚠️ The attack caused losses exceeding $300 million in DeFi https://t.co/SFVmjqAEXK

🚨 @KelpDAO decided to move rsETH to Chainlink CCIP 👀
📊 The step came after considering the @LayerZero_Core architecture as the main reason for the April hack
⚠️ The attack caused losses exceeding $300 million in DeFi https://t.co/SFVmjqAEXK
🚨 April 2026 was a harsh month for crypto 👀
📊
• 25 breaches in 29 days
• More than $629 million stolen
⚠️ Latest:
• Sweat Economy breach
• $3.46 million withdrawn (65% of supply) in just 30 seconds
⏱️ Rate:
One breach every 27 hours
💡 The month isn’t over yet… https://t.co/Vae1JWfX73
kelp’s intern hid this reply
that’s all you need to know
A ton of this is just completely untrue.
1) Kelp originally used the defaults which were MultiDVN or DeadDVN and manually migrated to a 1/1 config later
2) Almost 100% of the volume on a 1/1 config was rsETH
3) Not using a 1/1 for production applications is mentioned many times in the documentation.
The defaults Kelp is referencing in their screenshot were multiDVN or DeadDVN, which force-rejects an application using the defaults at all and requires them to manually set configuration.
rsETH was originally configured to use the default LayerZero configuration of a multiDVN setup of LayerZero Labs + Google:
Here are the exact transactions where that happens
Ethereum → Arbitrum:
https://t.co/C2uCxmpBCX
at 2024-02-06 03:09:47 UTC
Ethereum → Optimism:
https://t.co/vuQWxeyUUA
at 2024-02-06 03:09:59 UTC
KelpDAO then manually changed these to 1/1 configs:
For the original Feb 6 Ethereum routes to Arbitrum/Optimism, KelpDAO’s Ethereum contract switched from defaults to manual OApp-scoped config on 2024-04-0
Many things can be true regarding the Kelp & LayerZero exploit.
1. The LZ DVN got compromised.
2. LZ's default configuration is multi DVN, not a 1/1.
3. rsETH originally used LZ’s default multiDVN config (LayerZero Labs + Google)
4. Kelp manually changed its config from default to 1/1.
5. Kelp later deployed all configs as 1/1 setups.
6. Many LZ users still run 1/1 configs, but LZ discourages it for production code.
7. The 2/2 DVN setup of LZ + Nethermind processed the most volume among LZ security configs. 16/17 Nethermind admins are also admins on the LZ Labs DVN (94% overlap).
8. LZ comms should've been better after the incident.
9. There are still important questions that need answers from @LayerZero_Core, like those highlighted by @ChainLinkGod under Bryan's reply.
I believe that Kelp transitioning rsETH from LayerZero's OFT standard to @Chainlink's CCT standard is the safest and most logical alternative here.
But, for the sake of objectiveness, I'd also recommend reading @PrimordialAA's post underneath.
https://t.co/xwJeKdNPBL